forked from unom/punktfunk
180 commits since v0.27.0. Cut from origin/main9c133350. THE NUMBER: 0.28.0, not 0.27.1. The CHANGELOG's in-development section was titled "v0.27.1", which the release does not support — 17 `feat(...)` commits, a packager-visible default flip (GameStream opt-in on every route), the edition-2024 MSRV rise, and now a genuinely BREAKING host change (the built-in library scanners are deleted). `scripts/ci/pf-version.sh`'s canary rule agrees independently: CI already stamps canaries `0.28.<run>`. TWO DEFECTS FOUND AND FIXED WHILE PREPARING, both pre-existing on main: 1. C ABI_VERSION was stale at 18. Two exported symbols landed since v0.27.0 without a bump — punktfunk_connection_note_frame_index_ex and punktfunk_reanchor_gate_arm_expecting_drops (72 -> 74 declarations in include/punktfunk_core.h). The constant's own doc history makes the rule explicit: v17 and v18 each bumped for adding exactly one symbol. Bumped to 19 with its doc entry; the header is regenerated (cbindgen, CI-gated) and the C ABI harness passes printing abi_version=19. 2. docs-site/public/openapi.json had drifted to 0.21.0 against api/openapi.json, missing five endpoints. The copy is a documented manual step that nothing in CI enforces (CONTRIBUTING.md says so outright). Re-synced — and then it DRIFTED AGAIN inside this same cycle when the scanner-removal regen updated api/openapi.json alone, so it is re-synced a second time and the CHANGELOG now says to treat the copy as part of regenerating, not a follow-up. ⭐ The final docs batch also invalidated a line in this CHANGELOG: the identity section still said the P-256 key was "generated by ring via rcgen", which contradicted this same document's "ring is gone from the tree entirely". Corrected to "rcgen on the workspace's aws-lc-rs backend", matching92db6651. api/openapi.json stays stamped 0.27.0: it cannot be regenerated here (punktfunk-host does not compile on macOS) and does not need to be — the drift test normalizes info.version, so only the SURFACE is gated, and the surface is current. CHANGELOG: retitled to v0.28.0, gained the version table (wire 2 unchanged; C ABI 18->19; edition 2021->2024 and MSRV 1.82->1.85; driver protocol 6 and gamepad channel 3 unchanged; plugin-kit 0.4.0->0.4.1), a breaking-changes section, and ~29 topics the in-development text predated — including the four that landed last: the scanner->plugin migration, the Mutter rebuild serialization, the KWin <=60 Hz readback, and the Apple/Android de-prime fuse. ⭐ THE BREAKING ONE, stated plainly in both halves: the six built-in library scanners are DELETED and the library is assembled entirely by plugins. There is deliberately no migration — a plugin claims its store and republishes each title under the same `<store>:<external_id>` id, so entry ids, GameStream app ids, art caches, Moonlight pins, per-source toggles and per-entry hides all keep working. The one visible consequence, and the whole upgrade note: a host with NO library plugins installed has an empty grid. ⭐⭐ The Mutter two-client segfault this release now fixes (a5c9b7b8) is the one found during THIS release's on-glass validation: chaining two clients through a kept display killed gnome-shell in meta_monitor_manager_rebuild. It was A/B'd on .21 against the released 0.27.0 and shown byte-identical there, so it was never a 0.28.0 regression — and the fix's own commit message cites that A/B. GATES RUN, all green on this commit (re-run after the rebase onto86cbbea0): cargo fmt --all --check clean cargo metadata --locked OK against the new dependency tree Cargo.lock versions-only vs origin/main, 36/36 lines cargo test -p punktfunk-core 210 passed c_abi harness PASS, abi_version=19 (needs LIBRARY_PATH for opus on macOS; a link path, not a defect) docs-site build exit 0 (bun install --frozen-lockfile + build) Play notes gate 440/500 CHARACTERS, not byte-identical to any other release (`•` is 3 bytes — count characters, as the gate does) notes voice check 0 hits above `## For developers`; TL;DR at 6 bullets (README caps it at six) ON-GLASS (against the canary of14425716, code-identical bar ABI_VERSION): Windows .173 0.28.13309 + Android and iPad, Linux .21 0.28.0-0.00013300 + iPhone — both PASS. The idle sleep-blocker fix is proven before/after on .173 (`powercfg /requests` SYSTEM: the mic devnode -> "Keine."), and the GameStream flip is proven at the socket level on .21 (47984/47989/47999 absent by default, restored by PUNKTFUNK_GAMESTREAM=1). Old-client compat holds: Android 0.26.0 streams against the 0.28.0 host. ⏳ NOT re-validated: the Mutter fix itself. .21 (VM 103) is stopped — it and home-bazzite-2 (VM 119, currently running) share one passed-through GPU, so bringing .21 up would stop the other VM. Owed once .21 is free; the repro is iPhone 2868x1320 -> SIGTERM -> Android 2800x1260, and the marker to confirm the build carries the fix is the string "mutter: waited out a monitor-topology rebuild before releasing the lock". NOT INCLUDED: the 14 unpushed pf-capture/pf-vdisplay sweep commits on the local main. Never through CI; pushing them is the user's call.
128 lines
6.2 KiB
TOML
128 lines
6.2 KiB
TOML
[workspace]
|
|
resolver = "2"
|
|
members = [
|
|
"crates/punktfunk-core",
|
|
"crates/punktfunk-host",
|
|
"crates/punktfunk-host/vendor/usbip-sim",
|
|
# The capability-carrying PyroWave encode worker. A SEPARATE binary by design — never a
|
|
# hardlink of, or a subcommand of, punktfunk-host (design/gpu-priority-capability-worker.md).
|
|
"crates/punktfunk-encode-worker",
|
|
"crates/punktfunk-tray",
|
|
"crates/pf-bitstream",
|
|
"crates/pf-bitstream/vendor/cros-codecs",
|
|
"crates/pf-client-core",
|
|
"crates/pf-clipboard",
|
|
"crates/pf-presenter",
|
|
"crates/pf-console-ui",
|
|
"crates/pf-driver-proto",
|
|
"crates/pf-paths",
|
|
"crates/pf-update",
|
|
"crates/pf-update-check",
|
|
"crates/pf-host-config",
|
|
"crates/pf-gpu",
|
|
"crates/pf-zerocopy",
|
|
"crates/pf-frame",
|
|
"crates/pf-win-display",
|
|
"crates/pf-encode",
|
|
"crates/pf-capture",
|
|
"crates/pf-inject",
|
|
"crates/pf-vdisplay",
|
|
"crates/pf-vkdecode",
|
|
"crates/pf-dxvadec",
|
|
"crates/pf-vaadec",
|
|
"crates/pyrowave-sys",
|
|
"crates/libvpl-sys",
|
|
"clients/probe",
|
|
"clients/cli",
|
|
"clients/linux",
|
|
"clients/session",
|
|
"clients/windows",
|
|
"clients/android/native",
|
|
"tools/cursor-probe",
|
|
"tools/display-disturb",
|
|
"tools/latency-probe",
|
|
"tools/loss-harness",
|
|
]
|
|
# Standalone PoC (built on its own; pulls usbip/tokio/libusb we don't want in the workspace).
|
|
# The vendored `ndk` is a [patch.crates-io] source, not a member: it only compiles for the
|
|
# `*-linux-android` targets, so workspace membership would break host `cargo build --workspace`.
|
|
exclude = [
|
|
"packaging/linux/steam-deck-gadget/usbip-poc",
|
|
"clients/android/native/vendor/ndk",
|
|
# Bring-your-own-hardware measurement tools. `hid-descriptor-dump` pulls `hidapi`, a C library
|
|
# wanting libudev on Linux; `win-input-matrix` is Windows-only and asks the live input stacks
|
|
# what they can see. Neither belongs in `cargo build --workspace` or on a CI leg with no pad.
|
|
"tools/hid-descriptor-dump",
|
|
"tools/win-input-matrix",
|
|
]
|
|
|
|
# ndk 0.9.0 verbatim from crates.io plus ONE visibility change (and two warning fixes — an
|
|
# unnecessary `std::` qualification and a feature-gated `Result` import): `MediaCodec::as_ptr` made public
|
|
# (upstream keeps it private and exposes no frame-rendered binding), so the Android client can
|
|
# call `AMediaCodec_setOnFrameRenderedCallback` via ndk-sys for the HUD's `display` stage
|
|
# (design/stats-unification.md). Drop the patch when upstream exposes the pointer or the callback.
|
|
[patch.crates-io]
|
|
ndk = { path = "clients/android/native/vendor/ndk" }
|
|
|
|
[workspace.package]
|
|
version = "0.28.0"
|
|
edition = "2024"
|
|
rust-version = "1.85"
|
|
license = "MIT OR Apache-2.0"
|
|
authors = ["unom"]
|
|
repository = "https://git.unom.io/unom/punktfunk"
|
|
|
|
# The `unsafe` discipline the `packaging/windows/drivers/*` crates already run, extended to the
|
|
# workspace. `unsafe fn` marks a CONTRACT the caller must uphold; it is not a licence for the whole
|
|
# body to skip checking. Without this lint an `unsafe fn` body is unchecked end to end, so a 600-line
|
|
# function hides which handful of lines are actually the unsafe ones — exactly the reviewer-hostile
|
|
# shape we are working down. (This is the Rust 2024 default; adopting it early also pays off the
|
|
# edition migration.)
|
|
#
|
|
# `deny`, not `warn`. `warn` was never actually a softer setting: CI runs `cargo clippy … -D
|
|
# warnings`, which promotes it to a hard error anyway — that is how adopting this lint turned main
|
|
# red on every platform for a day without the level in this file ever saying `deny`. A level that
|
|
# lies about its own severity is worse than a strict one, so this now states what CI already does,
|
|
# and the exemptions are written down per file instead of hiding in a 689-warning wall nobody reads.
|
|
#
|
|
# THE EXEMPTIONS. Fourteen GPU/FFI backend files carry `#![allow(unsafe_op_in_unsafe_fn)]` with a
|
|
# one-line reason each. They are not "not done yet" — they are where this lint stops paying:
|
|
# their bodies are ash/CUDA/AMF/libav calls almost line for line (measured: 64% of the sites are a
|
|
# single third-party FFI call, and of the 44 `unsafe fn`s in them only 4 have a body containing no
|
|
# unsafe operation at all). Narrowing them means one `unsafe {}` per line plus, since pf-encode also
|
|
# denies `clippy::undocumented_unsafe_blocks`, one hand-written SAFETY comment per line that could
|
|
# only ever restate "an ash call on a live device" — the precise noise that made `unsafe` stop
|
|
# meaning anything here before (see the header of `pf-win-display/src/win_display.rs`).
|
|
#
|
|
# Everything else in the workspace is at zero and enforced. Removing one of those allows, file by
|
|
# file, is real work with a real payoff; blanket-narrowing all fourteen is not. Prefer DELETING an
|
|
# `unsafe fn` marker over wrapping its body: keep the marker only where a caller can actually break
|
|
# something (a raw pointer, a borrowed HANDLE, a GPU object that must not be in flight).
|
|
[workspace.lints.rust]
|
|
unsafe_op_in_unsafe_fn = "deny"
|
|
|
|
# The companion lint: every `unsafe {}` / `unsafe impl` carries a `// SAFETY:` proof. Hoisted here
|
|
# from ~85 per-file `#![deny(...)]` attributes so a NEW crate (or a new module in an old one) is
|
|
# covered on creation rather than on remembering — the per-file form left pf-vkhdr-layer,
|
|
# wdk-probe, and half of pf-clipboard uncovered for months. NOTE: this table reaches only crates
|
|
# with `[lints] workspace = true`; `packaging/windows/drivers` and `packaging/windows/pf-vkhdr-layer`
|
|
# are SEPARATE workspaces and restate it (any "workspace-wide" claim must be made three times or it
|
|
# is false). Of the members, only the two vendored snapshots (pf-bitstream/vendor/cros-codecs,
|
|
# punktfunk-host/vendor/usbip-sim) stay out, deliberately — upstream code stays pristine.
|
|
[workspace.lints.clippy]
|
|
undocumented_unsafe_blocks = "deny"
|
|
|
|
[profile.release]
|
|
opt-level = 3
|
|
lto = "thin"
|
|
codegen-units = 1
|
|
# NOTE: deliberately NOT `panic = "abort"`. punktfunk-core ships as a cdylib/staticlib into
|
|
# third-party apps (Swift/Kotlin/C) and its C ABI catches panics at the boundary
|
|
# (`catch_unwind` → `PunktfunkStatus::Panic`). `panic = "abort"` would make that guard a
|
|
# no-op and let a stray panic abort the embedding application. Unwinding keeps the
|
|
# documented isolation guarantee real.
|
|
|
|
# The per-frame hot path must stay fast even in dev builds.
|
|
[profile.dev.package."*"]
|
|
opt-level = 2
|